Source-linked AI summary
The European Union general data protection regulation: what it is and what it means
Chris Jay Hoofnagle, Bart van der Sloot, Frederik Zuiderveen Borgesius
TL;DR
The paper explains the GDPR’s foundations, development from the 1995 Data Protection Directive, provisions, and strategic implications, including its differences from U.S. privacy law. It concludes that the GDPR creates a complex protective regime that strengthens governance and enforcement, favors first-party relationships and human involvement, and constrains some information-intensive models.
Problem
The paper addresses how the GDPR regulates personal data, what normative and historical foundations support it, and how its approach differs from U.S. privacy law.
Method
The paper synthesizes the GDPR’s genesis, normative roots, major provisions, strategic goals, and comparisons with U.S. privacy law.
Results
The GDPR extends the Data Protection Directive into a complex, detailed, protective regime that strengthens governance and enforcement, elevates privacy officials, emphasizes accurate data and human involvement, and favors first-party relationships.
Takeaways & Limitations
The GDPR will influence personal-data use worldwide while complicating some information-intensive business models and enabling approaches previously unavailable under less-protective regimes.
Takeaways & Limitations
The GDPR’s length and complexity are its main disadvantage, and its effects on fairness and fundamental rights cannot yet be assessed conclusively.
Abstract
from arXiv · showhide
This paper introduces the strategic approach to regulating personal data and the normative foundations of the European Union's General Data Protection Regulation ('GDPR'). We explain the genesis of the GDPR, which is best understood as an extension and refinement of existing requirements imposed by the 1995 Data Protection Directive; describe the GDPR's approach and provisions; and make predictions about the GDPR's implications. We also highlight where the GDPR takes a different approach than U.S. privacy law. The GDPR is the most consequential regulatory development in information policy in a generation. The GDPR brings personal data into a detailed regulatory regime, that will influence personal data usage worldwide. Understood properly, the GDPR encourages firms to develop information governance frameworks, to in-house data use, and to keep humans in the loop in decision making. Companies with direct relationships with consumers have strategic advantages under the GDPR, compared to third party advertising firms on the internet. To reach these objectives, the GDPR uses big sticks, structural elements that make proving violations easier, but only a few carrots. The GDPR will complicate and restrain some information-intensive business models. But the GDPR will also enable approaches previously impossible under less-protective approaches.
1. Introduction
The paper presents the GDPR as a detailed, protective extension of European data-protection commitments that reshapes organizational data practices and business incentives. It emphasizes governance, stronger enforcement, human involvement, and advantages for first-party relationships.
- The GDPR is best understood as a detailed, protective regime that extends existing data-protection requirements and brings personal data into comprehensive regulation.The paper describes it as an extension and refinement of the 1995 Data Protection Directive and as a consequential development in information policy.
- The GDPR encourages companies to plan, evaluate, and govern personal-data collection, use, and destruction as strategic activities.Compliance can prompt firms to assess data’s value and treat it as a strategic asset.
- Stronger enforcement mechanisms and documentation requirements make privacy violations easier to prove and harder to treat as minor costs.The paper links penalties, breach notifications, and procedural records to deterrence and increased professionalization of data practices.
- The GDPR requires protections to follow personal data through service providers, diffusing contractual obligations across data-service relationships.Providers may experience these requirements as economic pressure from business associates rather than direct government coercion.
- The GDPR elevates privacy officials, favors human-in-the-loop decision-making, and is skeptical of low-quality consent as a legal basis for data use.Data Protection Officers document data practices, while correction and remediation rights support continued human involvement.
- First-party data relationships receive more favorable treatment than many third-party advertising uses, potentially reshaping internet commerce.The paper identifies possible advantages for publishers and proposes data infomediaries as a practicable model under the GDPR.
2. Background to the GDPR
European data protection developed from constitutional commitments and the expansion of Fair Information Practices beyond the narrower U.S. approach. The 1995 Data Protection Directive established the GDPR’s immediate foundation.
- Europe treats data protection as a distinct fundamental-rights commitment concerned with fair data use and due process.European protections extend beyond private life to communications, reputation, and personal-data processing.
- European law distinguishes privacy, focused on private life, from data protection, focused on fair and procedurally governed data processing.The distinction appears in European legal terminology and constitutional protections.
- European data-protection law applies Fair Information Practices broadly across government and private-sector information processing.The United States articulated FIPs but applied them more narrowly, while Europe deepened and expanded them.
- The 1995 Data Protection Directive created an omnibus regime covering most public- and private-sector processing after negotiations driven partly by EU internal-market concerns.The Directive provided the immediate legal platform from which the GDPR developed.
3. When does the GDPR apply?
The GDPR applies broadly to organizations that process personal data, including many organizations outside the EU, but excludes purely personal or household activities and largely excludes national security and criminal-law enforcement.
- Scope and definitions: The GDPR defines personal data broadly to include information that directly or indirectly identifies a person, including public, pseudonymous, location, and online-identifier data.Processing includes collecting, storing, disclosing, and erasing data, so organizations generally process personal data whenever they touch information relating to an individual.
- Regulated actors: Controllers determine processing purposes and means, while processors handle personal data on controllers’ behalf; the GDPR places substantial responsibility on controllers.Processors such as data centers or cloud providers must comply with many GDPR requirements, and controller responsibility can follow processor violations.
- Extraterritorial application: Organizations outside the EU may fall under the GDPR when they offer goods or services to people in the EU or consciously process their personal data.A physical EU presence is unnecessary; local language or currency can indicate an offer to Europeans, while mere website availability is insufficient.
- Extraterritorial application: Monitoring people in the EU, including behavioral tracking by third-party companies, can trigger the GDPR even without a European establishment.The paper identifies online tracking as a specific target of this rule, and notes that third-party tracking faces heavier requirements than comparable first-party uses.
- Exceptions: The GDPR exempts purely personal or household activities, but the exception is narrow and does not cover every activity conducted at home.Correspondence, address books, and social networking can qualify, whereas filming a home’s surroundings to identify burglars does not.
- Exceptions: National security and the prevention and prosecution of criminal offences are largely outside the GDPR’s scope, while other governmental processing may be governed by national special regimes.The Police Directive permits more limitations than the GDPR’s general framework.
- Conflicting interests: The GDPR balances data protection against transparency, speech, and archiving interests rather than treating data protection as unlimited.The paper contrasts this balancing approach with the U.S. tendency for freedom of speech to prevail when the values conflict.
4. Lawful data activities under the GDPR
The GDPR makes lawful data use a cumulative governance exercise built on Fair Information Practices and substantive limits on collection, reuse, and business models.
- Strategic approach: The GDPR’s data-governance approach requires companies to plan how they collect, use, and destroy data responsibly and parsimoniously.The framework may be viewed negatively as a constraint on data-intensive businesses or positively as a structured approach to information governance.
- Strategic approach: Fair Information Practices seek to minimize data collection and use, but collectively create barriers to big-data-driven business models.The paper presents these protections as both substantive safeguards against data-intensive companies and constraints on information-intensive industries.
- Core principles: The GDPR requires lawful data processing through cumulative high-level principles that controllers and processors must satisfy together.The principles include lawfulness, fairness, transparency, purpose limitation, and other Fair Information Practices inherited from the 1995 Directive.
- Purpose limitation: Purpose limitation requires collection for specified, concrete purposes and prohibits later uses that are incompatible with the original purpose.Compatibility depends on factors including the relationship between purposes, context, reasonable expectations, sensitivity, and consequences.
- Purpose limitation: Purpose limitation directly challenges information-intensive industries because companies frequently create value by reusing and repurposing data.The restriction therefore targets a central practice of data-driven business models.
4.2. The legal basis for processing personal data
The GDPR preserves six legal grounds for processing but imposes a higher, more substantive standard for consent than the notice-and-choice model associated with U.S. privacy law.
- Legal grounds: GDPR processing must satisfy the Fair Information Practices and rest on one of six specified legal grounds.The grounds include consent and processing necessary for a contract, among others.
- Consent: Unlike the U.S. notice-and-choice approach, GDPR consent must be freely given, specific, informed, unambiguous, and revocable.The paper describes U.S. privacy practice as relying heavily on changing policies and users’ marketplace choices.
- Consent: Valid GDPR consent requires a statement or clear affirmative action, so silence or failure to object cannot establish consent.Opt-out systems that treat non-objection as consent do not meet the unambiguous-indication requirement.
- Consent: The freely-given requirement often prohibits take-it-or-leave-it privacy conditions, including access conditioned on tracking for targeted marketing.The paper identifies tracking walls as a common example of the conditions this requirement challenges.
4.3. Sensitive data
The GDPR broadly defines sensitive data as special categories and generally prohibits processing them, creating particular difficulties for advertising practices that use identity-based segmentation.
- Special categories: The GDPR broadly defines special categories of personal data and explicitly prohibits their processing subject to exceptions.The categories include racial or ethnic origin, political opinions, religious or philosophical beliefs, trade-union membership, health, sex life, sexual orientation, and genetic data.
- Normative background: The European sensitivity to special-category data reflects historical abuses involving Nazi, Stasi, and Soviet regimes.The paper presents this history as part of the background for the Continental approach.
- Business implications: Sensitive data restrictions constrain advertising because marketers use racial and political identities to define consumer segments.The paper states that many exceptions to the processing ban are impracticable or unsuitable for most businesses.
- Exceptions: Consent for special-category data must be explicit, exceeding the GDPR’s already demanding general consent standard.Member States may strengthen the rule by eliminating the consent exception entirely.
- Exceptions: The GDPR permits processing when the data subject has manifestly made the special-category data public.This is identified as one exception to the general prohibition.
. for reasons of substantial public interest.141
The GDPR controls international transfers so that EU data protection is not evaded through less-regulated destinations. Transfers rely mainly on adequacy findings or contractual safeguards, while judicial scrutiny has made these arrangements vulnerable.
- International-transfer controls prevent companies from undermining EU data protection by moving personal data to less-regulated jurisdictions.
- The European Commission may approve countries with legal regimes offering adequate protection; the paper lists eleven approved jurisdictions.Approval normally follows negotiations that bring national regimes close to EU protection levels.
- Transfers to countries without adequacy decisions require organizations to contractually guarantee GDPR-like material and procedural safeguards.
- The Court of Justice invalidated Safe Harbor after finding broad government access and inadequate remedies inconsistent with fundamental rights.The paper notes that this reasoning could also threaten other transfer mechanisms.
5. Responsibilities for data controllers and processors
The GDPR assigns controllers primary responsibility for lawful data processing and requires documented governance, technical safeguards, independent oversight, risk assessment, and broad breach reporting. These duties make deviations easier to establish and extend protection through processors and service providers.
- Controllers retain primary responsibility while processors face stricter duties and liability when performing controller-like decision making.
- Controllers must keep detailed processing records and policies explaining data purposes, access, retention, accuracy, and related choices.The GDPR replaces the Directive’s impractical ex ante notification approach with documentation-centered accountability.
- Data controllers must provide clear information proactively and incorporate privacy by design and by default into technical infrastructure.Examples include pseudonymization, data minimization, and privacy-enhancing defaults.
- Large-scale or sensitive processing requires a protected Data Protection Officer to monitor compliance, advise the organization, and cooperate with authorities.The DPO’s independence creates trade-offs between internal knowledge and termination difficulty or external consultants’ incentives.
- Data Protection Impact Assessments are required for high-risk processing, including automated decisions, large-scale sensitive-data processing, and extensive public monitoring.A wrongful decision not to conduct a required DPIA is itself a GDPR violation.
- The GDPR defines personal-data breaches broadly, making many incidents previously treated as U.S. security incidents reportable under EU law.Losing a customer database containing emails and contact details is given as an example.
- Documentation of compliance, noncompliance, and breaches gives regulators an enforcement roadmap and makes deviations easier to investigate.
6. Rights of the data subject
The GDPR gives Europeans extensive control over personal data, including rights to access, rectify, erase, object to, and restrict processing. These rights continue protections already rooted in the Directive and constitutional instruments.
- Data subjects may access, rectify, and erase personal data, and may object to or restrict its processing.The paper presents these rights as continuing protections with roots in the Directive and constitutional instruments.
7. Enforcement
The GDPR strengthens enforcement through larger sanctions, expanded remedies, broader supervisory powers, and structural documentation duties. Enforcement may nevertheless be constrained by proportionality, authority workloads, and limited resources.
- The GDPR expands enforcement through sanctions, remedies, liability rules, stronger Data Protection Authorities, and class-action-like complaint mechanisms.
- Less serious violations can trigger fines up to €10 million or 2% of worldwide annual turnover, whichever is higher.
- More serious violations can trigger fines up to €20 million or 4% of worldwide annual turnover, whichever is higher.
- Facebook’s €150,000 2017 fine could theoretically have risen to €800 million–€1.6 billion under the GDPR.
- The paper expects early GDPR fines to remain below nine- and ten-figure amounts because sanctions must be proportional to offense seriousness.
- Broader breach reporting may become the primary practical punishment because regulators receive many more reports than under the narrower U.S. approach.
- Individuals can complain to Data Protection Authorities, seek judicial remedies, and use nonprofit-supported class-action-like mechanisms.
- Data Protection Authorities have broad investigative and intervention powers, but extensive duties and limited resources may restrict aggressive enforcement.
8. Conclusion
The GDPR extends and refines the 1995 Data Protection Directive while placing personal data within a more complex and protective regulatory regime. It introduces significant organizational and enforcement changes, but its length and complexity limit the paper’s treatment and leave its effects on fairness and fundamental rights for later assessment.
- The GDPR is best understood as an extension and refinement of the 1995 Data Protection Directive, retaining core data-protection principles.The paper describes these principles as comparable to the Fair Information Principles.
- The GDPR makes companies scrutinize personal-data practices, vet service providers, elevate privacy officials, and address data accuracy and access rights.Organizations cannot always rely on consent, because the GDPR is skeptical of informed consent as a legal basis in some circumstances.
- The GDPR is expected to strengthen first-party relationships with individuals while prompting continued disputes between Data Protection Authorities and large technology companies.
- The GDPR’s main disadvantage is its length and complexity, comprising 99 detailed provisions.
- Whether the GDPR improves fairness and respect for fundamental rights can only be assessed after it has applied for some time.
- The GDPR signals a new phase in privacy law, while European rules on fair processing will require continual updating as circumstances change.